{"id":12006,"date":"2026-09-11T11:56:30","date_gmt":"2026-09-11T17:56:30","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/"},"modified":"2026-09-29T13:59:33","modified_gmt":"2026-09-29T19:59:33","slug":"alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/","title":{"rendered":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected product(s):<\/h2>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product \/ service<\/strong><\/td><td><strong>Vulnerability<\/strong><\/td><td><strong>Impact<\/strong><\/td><td><strong>Status<\/strong><\/td><\/tr><tr><td><strong>Cisco Secure Firewall Management Center (FMC) Software<\/strong><\/td><td>CVE\u20112026\u201120079<\/td><td>Authentication bypass and remote execution of scripts\/commands as root<\/td><td>Confirmed active exploitation<\/td><\/tr><tr><td><strong>Cisco Secure Firewall Management Center (FMC) Software<\/strong><\/td><td>CVE\u20112026\u201120316<\/td><td>Unauthenticated remote login with a static low-privilege account; possible escalation through chaining with other flaws<\/td><td>Confirmed active exploitation<\/td><\/tr><tr><td><strong>Cisco Security Cloud Control Firewall Management<\/strong><\/td><td>CVE\u20112026\u201120079<\/td><td>Cloud service<\/td><td>Cisco indicates it has already been fixed by the vendor<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">Active exploitation of two vulnerabilities in <strong>Cisco Secure Firewall Management Center (FMC)<\/strong> has been reported: <strong>CVE\u20112026\u201120079<\/strong> (CVSS 10.0), an authentication bypass that allows execution of commands as root, and <strong>CVE\u20112026\u201120316<\/strong> (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters to steal credentials, deploy webshells, and, in at least one case, facilitate the deployment of <strong>Qilin<\/strong> ransomware.<\/p>\n\n<p class=\"wp-block-paragraph\">Both vulnerabilities are detailed below:<\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE\u20112026\u201120079 \u2014 Authentication Bypass \/ RCE as root: <\/strong>It has <strong>critical<\/strong> severity and CVSS <strong>10.0<\/strong>. The vulnerability originates in a system process incorrectly created during FMC startup. An unauthenticated remote attacker can send crafted HTTP requests to the web interface of a vulnerable FMC, bypass authentication, and execute scripts or commands with root privileges on the underlying operating system.<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li><strong>CVE\u20112026\u201120316 \u2014 Static credentials: <\/strong>It has a CVSS score of <strong>5.3<\/strong> and is due to the presence of static credentials for a low-privilege account in FMC. An unauthenticated remote attacker can authenticate with that account and access sensitive information on the affected system. Cisco warned that this flaw can be combined with other Secure FMC vulnerabilities to elevate privileges and increase the impact.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Indicators of possible compromise<\/h2>\n\n<p class=\"wp-block-paragraph\">Cisco recommends examining \/var\/log\/messages in FMC for references to \/var\/tmp\/license.tmp. The following event indicates that the vulnerability <strong>may have been exploited<\/strong> and requires immediate investigation:<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Jul 23 16:16:33 firepower sudo: www : PWD=\/ ; USER=root ; COMMAND=\/usr\/local\/sf\/bin\/package_info.pl \/var\/tmp\/license.tmp &#8211;lsm<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">The following should also be investigated as potential indicators:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Unrecognized or recently modified JSP files on the FMC system.<\/li>\n\n\n\n<li>Unusual JAR files used to execute commands.<\/li>\n\n\n\n<li>Processes or network connections associated with nc\/Netcat, especially persistent outbound connections.<\/li>\n\n\n\n<li>Unauthorized Bash scripts and suspicious scheduled tasks.<\/li>\n\n\n\n<li>Unknown ELF files, binaries, or processes that could be linked to Cyclops Blink.<\/li>\n\n\n\n<li>Unauthorized queries to internal databases, anomalous accesses to authentication data, or credential modifications.<\/li>\n\n\n\n<li>Unusual use of built-in FMC tools for network discovery, configuration collection, or device management.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n<p class=\"wp-block-paragraph\">Cisco released specific <em>hotfixes<\/em> for the affected versions of Secure FMC, for both <strong>CVE\u20112026\u201120079<\/strong> and <strong>CVE\u20112026\u201120316<\/strong>. The organization should apply both fixes, not just the one corresponding to CVE\u20112026\u201120079, given that individual and combined use of both vulnerabilities has been observed in real intrusions.<\/p>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/csa\/cisco-sa-fmc-static-cred-BET3Cjh.html\">https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/csa\/cisco-sa-fmc-static-cred-BET3Cjh.html<\/a><\/li>\n\n\n\n<li>https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-onprem-fmc-authbypass-5JPp45V2<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">BleepingComputer \u2014 Cisco confirms CVE\u20112026\u201120079 Secure FMC flaw exploited in attacks<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/thehackernews.com\/2026\/09\/cisco-fmc-flaws-exploited-to-steal.html\" target=\"_blank\" rel=\"noreferrer noopener\">The Hacker News \u2014 Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/csa\/cisco-sa-fmc-static-cred-BET3Cjh.html\">https:\/\/www.cisco.com\/c\/en\/us\/support\/docs\/csa\/cisco-sa-fmc-static-cred-BET3Cjh.html<\/a><\/li>\n\n\n\n<li>https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-onprem-fmc-authbypass-5JPp45V2<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"featured_media":10969,"template":"","class_list":["post-12006","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\u20112026\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\u20112026\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\u20112026\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\u20112026\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/08\/CISCO-FMC.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/08\/CISCO-FMC.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"225\" \/>\n\t\t<meta property=\"og:image:height\" content=\"225\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-11T17:56:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T19:59:33+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\u20112026\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\u20112026\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/08\/CISCO-FMC.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#listItem\",\"name\":\"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/\",\"name\":\"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC - Beacon Lab\",\"description\":\"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\\u20112026\\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\\u20112026\\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/CISCO-FMC.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#mainImage\",\"width\":225,\"height\":225},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\\\/#mainImage\"},\"datePublished\":\"2026-09-11T11:56:30-06:00\",\"dateModified\":\"2026-09-29T13:59:33-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC - Beacon Lab","description":"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\u20112026\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\u20112026\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#listItem","name":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#listItem","position":2,"name":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/","name":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC - Beacon Lab","description":"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\u20112026\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\u20112026\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/08\/CISCO-FMC.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#mainImage","width":225,"height":225},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/#mainImage"},"datePublished":"2026-09-11T11:56:30-06:00","dateModified":"2026-09-29T13:59:33-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC - Beacon Lab","og:description":"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\u20112026\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\u20112026\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/08\/CISCO-FMC.png","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/08\/CISCO-FMC.png","og:image:width":225,"og:image:height":225,"article:published_time":"2026-09-11T17:56:30+00:00","article:modified_time":"2026-09-29T19:59:33+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC - Beacon Lab","twitter:description":"Affected product(s): Description Active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) has been reported: CVE\u20112026\u201120079 (CVSS 10.0), an authentication bypass that allows execution of commands as root, and CVE\u20112026\u201120316 (CVSS 5.3), associated with the use of static credentials for a low-privilege account. Both flaws have been used by different threat clusters","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2025\/08\/CISCO-FMC.png"},"aioseo_meta_data":{"post_id":"12006","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 19:58:35","updated":"2026-09-29 20:56:20","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-100 Active exploitation of critical vulnerabilities in Cisco Secure FMC","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-100-active-exploitation-of-critical-vulnerabilities-in-cisco-secure-fmc\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12006","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12006\/revisions"}],"predecessor-version":[{"id":12007,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/12006\/revisions\/12007"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/10969"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=12006"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}